handoff
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill creates an attack surface for indirect prompt injection by summarizing untrusted conversation data into a handoff document and suggesting skills based on that data. * Ingestion points: Current conversation history. * Boundary markers: Absent; no delimiters are used to separate conversation content from summarization instructions. * Capability inventory: File-write access to the operating system's temporary directory. * Sanitization: Includes explicit instructions for the agent to redact sensitive information such as API keys, passwords, and PII.
- [NO_CODE]: The skill consists only of natural language instructions and does not include any executable scripts, binaries, or code files.
Audit Metadata